W3C home > Mailing lists > Public > public-webappsec@w3.org > September 2015

Re: CSP3 as a polylithic set of modules?

From: Brian Smith <brian@briansmith.org>
Date: Mon, 28 Sep 2015 12:08:25 -1000
Message-ID: <CAFewVt5Rde97Ma95utSABA=zNNvx687duKT1uG2=CyqAXiEpGg@mail.gmail.com>
To: Joel Weinberger <jww@chromium.org>
Cc: Mike West <mkwst@google.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, Brad Hill <hillbrad@gmail.com>, Dan Veditz <dveditz@mozilla.com>, Mark Nottingham <mnot@mnot.net>, Travis Leithead <Travis.Leithead@microsoft.com>
On Mon, Sep 28, 2015 at 11:44 AM, Joel Weinberger <jww@chromium.org> wrote:

> While I like the maintainability of this proposal, it seems like it might
> complicated the versioning that Dev has proposed in the past (that I really
> like). Namely, for each sub-spec, you'd have to tie it into a specific CSP
> version you'd like it to be in, and tracking all of that information down
> across specs might be difficult. But if we want versioning, maybe it's
> still worth figuring out how to do it well across distributed chunks like
> this.

I see Mike's proposal as a way towards avoiding versioning. I think it is
worth trying to avoid versioning. It's not clear what issues that people
are proposing to solve with versioning, though.

Received on Monday, 28 September 2015 22:08:52 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:52 UTC